← vinca.chat

Courtesy translation — the French version is the legally binding one. Read the French version

Privacy Policy — vinca.chat

Version 1.9

The essentials in brief

  • Vinca is an artificial intelligence, not a healthcare professional. It makes no diagnosis, prescribes no treatment and does not replace a doctor, a psychologist or any other qualified professional.
  • Your conversations may contain highly intimate information (emotional state, relationship life, sexual life). We treat them as health data and data concerning sex life within the meaning of Article 9 of the GDPR, with your explicit consent.
  • Your data is stored encrypted in Paris (AES-256-GCM, one encryption key per user). This encryption protects your data at rest; it is not end-to-end encryption: our servers must decrypt your messages in order to query the AI.
  • Your data is never sold, never used for advertising purposes, and never used to train the AI models.
  • You can delete your account at any time from "My account": your conversations and memories are then erased immediately and permanently.
  • The service is reserved for adults (18 years and older).

This page summarizes the essentials; the sections below detail the entirety of our practices.


1. Who is responsible for your data?

The controller of your personal data (Art. 4.7 and 13.1.a of the GDPR) is:

Global Human Intelligence Consulting (GHIC)

Single-member limited liability company with capital of €100

Registered with the Paris Trade and Companies Register under number 939 603 593

Intra-community VAT number: FR06939603593

Registered office: 60 rue François 1er, 75008 Paris, France

Manager: Philippe Guillamo

Contact: contact@vinca.chat · +33 1 84 16 38 76

GHIC is established in the European Union; no representative within the meaning of Article 27 of the GDPR therefore needs to be designated.

The legal notices of the website's publisher (identity of the publisher, publication director, host — Art. 1-1 of French Act No. 2004-575 of 21 June 2004, known as the LCEN) are the subject of a separate document, accessible from the footer of vinca.chat.

2. "Data protection" contact

GHIC has not designated a data protection officer (DPO) at this stage, given the size of the service; this situation will be reviewed as the number of users grows. For any question relating to your personal data or to exercise your rights (see section 12), you may write to:

contact@vinca.chat — suggested subject: "Personal data"

or by post: GHIC — Data Protection, 60 rue François 1er, 75008 Paris, France.

3. Vinca is an artificial intelligence, not a healthcare professional

In accordance with Article 50 of Regulation (EU) 2024/1689 on artificial intelligence and with the CNIL's recommendations on conversational agents, we clearly inform you that:

  • You are conversing with an artificial intelligence, not with a human being. Vinca's responses are generated automatically by language models; they may be inaccurate, incomplete or unsuited to your situation.
  • Vinca is an emotional and relational well-being companion. It is neither a healthcare professional nor a care service: Vinca makes no diagnosis, prescribes no treatment and provides no medical advice. The service is not a medical device within the meaning of Regulation (EU) 2017/745. It in no way replaces a consultation with a doctor, a psychologist, a psychiatrist or any other qualified professional — whom we expressly recommend that you consult for any critical or persistently difficult situation.
  • Vinca is not an emergency service. If you are going through a crisis, have suicidal thoughts or are in danger, contact the competent services immediately. In France: 3114 (national suicide prevention number, free, 24/7) and 112 (life-threatening emergencies). The application permanently displays, below the conversation, the help numbers appropriate to your country, as well as the notice "Vinca is an AI and does not replace a healthcare professional."

4. What data do we collect?

CategoryContentMandatory / optional nature
Account dataFirst name, email address, date of birth (used solely to verify that you are 18 years of age or over — see section 17), password (stored in hashed form, never in plain text) or linked Google account (see below), preferred language, your device's time zone (so that a reminder you ask for at 6 p.m. actually reaches you at 6 p.m. where you are — see "Scheduled reminders" below), date of your last activity and counter of the re-engagement emails that have been sent to you (see section 7); where applicable, two-factor authentication (2FA) secret, stored encryptedMandatory: without an email address, a date of birth and a sign-in method (password or Google account), the account cannot be created
Google sign-in (if you choose this sign-in method)Data received from Google: email address and its verification status, name associated with the Google account (pre-fills your first name, which you can edit), technical identifier of the account (the "sub" field), retained to recognize your account — details below this tableOptional: sign-up and sign-in with an email address and password always remain available
ConsentsBoxes ticked at sign-up, at the time of purchases and when creating or joining a shared space (adulthood, health data, immediate performance, distillation), with date and timeMandatory (legal proof of consent)
Conversation contentMessages you exchange with Vinca, in your private space or in a couple/family space, stored encryptedFreely provided by you: you choose what you confide to Vinca
MemoriesLasting facts extracted from your conversations by a background AI (for example your family situation, your recurring concerns), stored in English and encrypted — private memory (individual) and shared memory (per couple/group)Generated automatically from what you confide; "remember" / "forget" commands available to you
Voice messagesAudio recording transcribed into text; the audio is not retained: only the transcribed text becomes a messageOptional: the keyboard always remains available
ImagesImages you attach to a message; they are analyzed by the AI and then not retained (a 📷 marker remains in the history)Optional
Guided test resultsAnswers and summaries of the guided psychological tests offered by the application — presented as tools for reflection, never as diagnoses —, stored encrypted; history viewable, tests retakeableOptional: each test is offered, never imposed
Payment dataHistory of credit purchases, balance, invoices. Bank card data is collected directly by Stripe and never passes through our serversMandatory only in the event of a purchase
Credit giftIf you gift a pack of credits to another user: the email address of the recipient account that you enter (verification of the existence of that account is strictly limited — 5 attempts per day and per account, with a neutral response beyond that — see section 7); your own email address as the giver, frozen at the time of the gift, shown to the recipient upon their next sign-in and then kept in their credit history as the origin of the gift (section 10); a gift entry linked to the payment historyOptional: only if you give or receive a credit gift
Inviting a loved one by emailThe email address of the loved one that you enter, used solely to send the invitation email — content strictly limited to the invitation, with no reuse of the address and no subsequent message —, then neither retained nor logged beyond the technical needs of the sending; a sending counter without the address (limit of 5 sendings per account per 24 hours); where applicable, a referral code linked to the referred user's account when they first joinOptional: only if you use the invitation feature
Technical logsService operation logs (errors, security events), retained for 30 daysGenerated automatically (operation and security of the service)
Acquisition and visit dataThe source through which you learned of the service (campaign link, referring site), remembered in a cookie specific to vinca.chat and, if you create an account, linked to it; anonymous, aggregated visit statistics. Never cross-referenced with the content of your conversationsGenerated automatically; right to object (section 12)
Crisis event logWhen the crisis protocol is triggered at a serious level (section 15), we record technical metadata (date, level, language, country) — never the content of your conversation — and, for certain AI responses, short excerpts of the response intended for a human safety reviewGenerated automatically, for your safety and the oversight of the crisis protocol
Notification subscriptionIf you enable notifications, the technical subscription identifier provided by your browser (delivery address and channel encryption keys), your chosen language, and your choice whether or not to display the subject of your reminders in the notification. The content of the notifications is generic by default: never the content of your conversations or of your memories — the only exception, at your express request, being the subject of the reminders you have yourself scheduled (see section 16)Optional: double voluntary action (browser permission + button in "My account"), can be disabled at any time
Suggestions and feedbackIf you write to us from "Suggestions": the text you compose, stored encrypted, your first name and your email address (to reply to you or to thank you), and the language in which you write it. This form is not an emergency channel: it is not monitored continuously, and the page says soOptional: only if you write to us
Scheduled remindersIf you ask Vinca to remind you of something: the subject of the reminder as you word it, its date and time, and the time zone in which you asked for it — stored encrypted. A reminder requested in a shared space belongs to that space and notifies its members. You can view them and cancel them at any time in "My path"Optional: only if you ask for a reminder
Display preferencesSettings stored locally on your device (see section 16)Optional

We collect no browsing data for advertising purposes, and we neither buy nor resell any data. Our audience measurement relies exclusively on anonymous statistics established by our own servers and on a provenance cookie placed by vinca.chat only (see section 16) — never on a third-party service.

Google sign-in (optional)

You can create your account or sign in using your Google account ("Sign in with Google"). This feature is entirely optional: sign-up and sign-in with an email address and password always remain available.

  • Data received from Google. Google transmits to us only: your email address (and its verification status), the name associated with your Google account (used to pre-fill your first name, which you can freely edit) and the technical identifier of your Google account (the "sub" field), which we retain in order to recognize your account on your subsequent sign-ins. We receive neither your Google password, nor your contacts, nor any other data from your Google account.
  • Legal basis. Performance of the contract (Art. 6.1.b of the GDPR): this processing is strictly necessary for the provision of the sign-in method you have chosen.
  • Google's role. For the authentication itself (the "Sign in with Google" page and the processing it entails on Google's side), Google acts as an independent controller — not as our processor. That processing is governed by Google's privacy policy: policies.google.com/privacy.
  • No Google tracker on vinca.chat. This feature places no Google cookie or script on our site: it relies on a redirection to Google's sign-in page, followed by a secure return to vinca.chat (see section 16).
  • Your rights. The Google technical identifier is included in the export of your data ("My account → My data") and is erased upon deletion of your account, like the rest of your account data.

5. Health data and data concerning sex life: your explicit consent

By its very nature, an emotional and relational well-being companion leads you to discuss your psychological and emotional state, your relationship, and sometimes your sexual life. This information falls within the special categories of data of Article 9 of the GDPR (health data; data concerning sex life or sexual orientation), the processing of which is in principle prohibited.

We process this data on the basis of your explicit consent (Art. 9.2.a and 6.1.a of the GDPR), collected at sign-up through a dedicated tick box, never pre-ticked, distinct from acceptance of the general terms and conditions, and time-stamped in our database.

Withdrawal of consent. You may withdraw your consent at any time, as easily as you gave it (Art. 7.3 of the GDPR), by deleting your account from "My account" or by writing to us at contact@vinca.chat. Consequences: the conversational service can no longer be provided to you (it relies entirely on this processing) and your conversations and memories are erased; the processing carried out before withdrawal remains lawful.

Specific protection measures. This data benefits from the measures described in section 11: AES-256-GCM encryption with an encryption key specific to each user and each group ("envelope encryption" via a key management service), storage exclusively in Paris, strict segregation between private memory and couple space (see section 6).

6. Data concerning persons other than you (partner, relatives)

When you talk to Vinca about your partner, your children or your relatives, you indirectly transmit information concerning them — sometimes sensitive. The GDPR (Art. 14) in principle requires that these persons be informed. Here is how we handle this situation, specific to relationship-support services:

  • Watertightness of your private memory. The memories arising from your private conversations are never injected as is into a couple or family conversation. Only a "distillation" — general guidance, stripped of any identifiable fact — may inform shared conversations. You alone may, through a deliberate and explicit action, transfer the content of a conversation to the shared memory.
  • Information for the invited partner. When a person joins your couple or family space, they create their own account and accept this policy. They are furthermore informed, through a dedicated notice displayed both when creating and when joining a shared space (in the eight languages of the interface), that data concerning them may have been mentioned in the service before their arrival (information under Article 14 of the GDPR — feature in place since July 5, 2026).
  • Third parties who will never become users (children, ex-spouses, colleagues, family members mentioned in conversation): informing them individually would require identifying and contacting them, which would be impossible or involve a disproportionate effort, and would undermine the confidentiality of your exchanges. We rely on the exemption of Article 14.5.b of the GDPR and, in accordance with it, make the information public via this section. This third-party data benefits from the same protections (encryption, absence of sharing, erasure with your account) as your own.
  • The loved one you invite by email. You may ask Vinca to send, on your behalf, an invitation email to a loved one (feature in place since July 2026). The email address you enter is used exclusively for that single sending, triggered by you: it is neither retained nor logged by our systems beyond the technical needs of the sending, is never reused and gives rise to no reminder message or any other solicitation. The information due to the loved one (Art. 14 of the GDPR) is provided by the invitation email itself — which states who is inviting them (your first name), specifies that Vinca is an artificial intelligence reserved for adults and points out that their address is not retained — as well as by this section; only our sending processor (Brevo, section 8) processes their address, under the conditions and for the periods described in sections 8 and 10. The loved one remains entirely free not to respond and may, like you, exercise the rights described in section 12 by writing to contact@vinca.chat.

We ask you, for your part, to disclose about third parties only what is necessary for your support.

7. Why do we process your data, and on what legal basis?

In accordance with Article 13.1.c of the GDPR, each purpose rests on its own legal basis:

PurposeLegal basisDetails
Creation and management of the account, authentication (including 2FA), preferencesContract (Art. 6.1.b)Necessary for the provision of the service you subscribed to
Sign-in with your Google account (delegated authentication, optional)Contract (Art. 6.1.b)Necessary for the provision of the sign-in method you have chosen; Google is an independent controller for the authentication (section 4)
Age verification (18 years of age or over) based on your date of birthContract (Art. 6.1.b) + legitimate interest (Art. 6.1.f)The service is reserved for adults (section 17); interest pursued: the protection of minors
Conversations with the AI, including health data and data concerning sex lifeExplicit consent (Art. 9.2.a + 6.1.a)Dedicated box at sign-up, withdrawal possible at any time (section 5)
Extraction and encrypted storage of memories (private and shared memory)Explicit consent (Art. 9.2.a + 6.1.a)"Remember" / "forget" commands available
Distillation of private memory to the couple/family spaceDistinct explicit consent (Art. 9.2.a + 6.1.a)Dedicated box, mandatory and never pre-ticked, presented both when creating and when joining a shared space, time-stamped in the database (feature in place since July 5, 2026)
Transcription of voice messages (audio transmitted to OpenAI)Consent (Art. 6.1.a / 9.2.a)Optional feature, triggered only by your action; audio not retained
Analysis of attached imagesConsent (Art. 6.1.a / 9.2.a)Optional feature; images not retained
Payment, invoicing, credit management (including optional automatic top-up)Contract (Art. 6.1.b) + legal obligation (Art. 6.1.c; Art. L.123-22 of the French Commercial Code)Automatic top-up: only upon express time-stamped consent, deactivable in one click
Credit gift: purchase of a pack for the benefit of another user, verification of the existence of the recipient account, information of the recipient (giver's email address)Contract (Art. 6.1.b) + legal obligation (Art. 6.1.c; Art. L.123-22 of the French Commercial Code) for the gift entries; legitimate interest (Art. 6.1.f) for the anti-abuse limitationVerification limited to 5 attempts per day and per account, with a neutral response beyond that, in order to prevent any systematic probing of the existence of accounts (enumeration); interest pursued: the prevention of abuse
Sending, at your request, of an invitation email to a loved one, and awarding of the referral creditLegitimate interest (Art. 6.1.f) as regards the loved one's address; contract (Art. 6.1.b) for the awarding of the referral creditSingle sending triggered by you and in your name, with no reuse of the address and no subsequent message (framework defined by the CNIL for referral schemes); the loved one's address is deleted after the sending; limit of 5 sendings per account per 24 hours; credit awarded to the referrer and the referred user only once per account (section 4)
Transactional emails (sign-up confirmation, forgotten password, receipts)Contract (Art. 6.1.b)No commercial solicitation without separate consent
Improvement of the service on the basis of your suggestions and feedback (reading by the controller, possible thank-you in credits)Legitimate interest (Art. 6.1.f)Interest pursued: correcting and improving a young service on the basis of what its users say about it. You alone decide to write; the text is read by the controller, never published or transmitted to a third party; deletion on request; right to object (section 12)
Re-engagement of inactive accounts: up to three emails inviting you to come back, sent from vinca@vinca.chatLegitimate interest (Art. 6.1.f)Interest pursued: reactivating an account that you opened and left unused. These emails contain no conversation content and no memories; at most three sendings (1, then 3, then 5 days after your last activity); any new sign-in resets the counter to zero; one-click unsubscribe link in every email; right to object (section 12)
Security of the service, technical logs, prevention of fraud and abuseLegitimate interest (Art. 6.1.f)Interest pursued: guaranteeing the security, integrity and availability of the service and preventing fraudulent uses; logs limited to 30 days
Display of help numbers appropriate to your countryContract (Art. 6.1.b)Security feature integrated into the service
Measurement of the effectiveness of our communication actions (acquisition source) and aggregated usage statisticsLegitimate interest (Art. 6.1.f)Interest pursued: developing and sustaining the service. Data with no link whatsoever to the content of your conversations; no transmission to third parties; right to object (section 12)
Logging of crisis protocol triggers and safety review of the AI's responsesExplicit consent (Art. 9.2.a + 6.1.a), under the crisis protocol; legitimate interest (Art. 6.1.f) in supportMetadata without conversation content; short excerpts of the AI's responses only, for human verification of the safeguards (see sections 4, 10 and 15)
Sending of the notifications you have enabled (reminders you schedule, at the time you requested; a discreet reminder the day before an important date you have confided to Vinca; checking in with you the day after a difficult moment)Consent (Art. 6.1.a; Art. 82 of Act No. 78-17 for access to your device)Voluntary activation in "My account"; at most one anticipatory notification per day, plus the reminders you have yourself asked for and nothing else; content generic by default, the subject of a reminder being displayed only if you have enabled it; disabling as simple as enabling (section 16)

We pursue no advertising, commercial-profiling or data-resale purpose. Any new purpose based on consent (for example the use of conversations to improve the service) would be the subject of distinct and prior consent.

8. Who receives your data? (processors and recipients)

Your data is accessible only to the processors strictly necessary for the operation of the service (Art. 28 of the GDPR), listed by name below:

ProcessorRoleLocation of processingSafeguardsData received
Google Cloud (Google Cloud EMEA Ltd)Hosting of the application and the databaseData stored in Paris (europe-west9 region); stateless computation (Cloud Run application servers) in Belgium (europe-west1)Processing contract (Cloud Data Processing Addendum), data hosted in the EU, encryption at restAll hosted data (conversations and memories encrypted at the application level)
Anthropic (Anthropic Ireland Ltd / Anthropic PBC)Provision of the AI models that generate Vinca's responses and extract the memoriesUnited States (for the duration of the processing of each request)DPA with standard contractual clauses (SCC); no use of your data to train the models (contractual behavior of the API); automatic deletion of inputs and outputs within 30 days (default operational retention, verified on 2026-07-05)The content of your conversations and the relevant memories, decrypted — this is technically indispensable: the model must read the text in order to respond (see sections 9 and 11)
OpenAI (OpenAI Ireland Ltd / OpenAI LLC)Only the transcription of voice messages into textUnited StatesDPA with standard contractual clauses (SCC); no use of your data to train the models; the audio transcription endpoint operates without data retention (verified on 2026-07-05)The audio file to be transcribed, and nothing else; the audio is not retained by Vinca after transcription
Stripe (Stripe Payments Europe Ltd / Stripe, LLC)Card payment processingEU / United StatesPCI-DSS certification; Data Privacy Framework (active registration of Stripe, LLC verified on 2026-07-05) and standard contractual clausesYour email address and the transaction information; in the event of a credit gift, a technical identifier of the recipient account (never their email address). Your card data is entered directly with Stripe and never passes through our servers
Brevo (Sendinblue SAS)Sending of transactional emails and, at your request, of invitation emailsFrance / EUFrench processor, emails processed on infrastructure hosted in the EU; certain of Brevo's cross-cutting sub-processors (CDN, monitoring, support) are established outside the EU with DPF safeguards and/or standard contractual clauses (verified on 2026-07-05)Your email address, your first name and the content of service emails; if you use the invitation feature, the email address of the invited loved one, for that sending only

No other commercial recipient exists. Certain other users of the service may, however, receive data concerning you, at your initiative only: the recipient of a credit gift sees your email address (that of the giver, frozen at the time of the gift — sections 4 and 10); the loved one you invite receives an email stating that the invitation comes from you (your first name appears in it). Symmetrically, the person who gifts you a pack of credits thereby learns that your email address corresponds to a Vinca account — it is precisely to limit this risk that verification is capped and made neutral beyond the limit (section 7). Your data may furthermore be communicated to the administrative or judicial authorities where the law requires us to do so (a judicial requisition, for example).

The transfer impact assessment (TIA) common to Anthropic and OpenAI was recorded on July 5, 2026 in the DPIA.

9. Does your data leave the European Union?

Your data is stored in France (Paris). Certain processing operations, however, involve a temporary transfer outside the European Union:

  • Anthropic (United States). To generate each response, the content of the conversation is transmitted to Anthropic's servers in the United States, for the duration of the processing. This transfer is governed by the standard contractual clauses of the European Commission (Art. 46.2.c of the GDPR), incorporated into Anthropic's Data Processing Addendum (EU contracting party: Anthropic Ireland Ltd). Anthropic does not use this data to train its models, and automatically deletes inputs and outputs from its servers within 30 days (default operational retention of the API, verified on July 5, 2026 and documented in the TIA).
  • OpenAI (United States). Voice messages (audio only) are transmitted to OpenAI for transcription, on the basis of the standard contractual clauses incorporated into OpenAI's Data Processing Addendum (EU contracting party: OpenAI Ireland Ltd). OpenAI does not use this data to train its models; for this audio transcription endpoint, OpenAI applies no data retention by default (verified on July 5, 2026). The option of European data residency for the OpenAI API remains under study (it is conditional on commercial validation by OpenAI).
  • Stripe (United States). Payment data may be processed in the United States, on the basis of the EU–United States Data Privacy Framework (active registration of Stripe, LLC verified on July 5, 2026) and, subsidiarily, of the standard contractual clauses of its DPA.
  • Google Cloud. Your data is stored in Paris: there is no structural transfer. Any residual support access from the United States is covered by Google's transfer safeguards (Data Privacy Framework — active registration of Google LLC verified on July 5, 2026 — and standard contractual clauses).
  • Brevo. Processing and hosting of emails in the EU (France); certain of Brevo's cross-cutting sub-processors (CDN, monitoring, support) are established outside the EU, with DPF safeguards and/or standard contractual clauses (verified on July 5, 2026).

The verification of the status of each entity on the official Data Privacy Framework list (dataprivacyframework.gov) was carried out on July 5, 2026: Google LLC and Stripe, LLC are registered and active there; Anthropic and OpenAI do not appear on it. Transfers to Anthropic and OpenAI therefore rely solely on the standard contractual clauses of their DPAs — a legally sound position, the DPAs themselves providing for the switch between mechanisms.

You may obtain a copy of the applicable safeguards (standard contractual clauses) by writing to us at contact@vinca.chat.

10. How long do we retain your data?

DataRetention period
Conversations and memoriesAs long as your account is active. Upon account deletion: immediate purge (see below)
Images attached to messagesNot retained: analyzed and then deleted immediately (only a 📷 marker remains in the history)
Voice messages (audio)Not retained: deleted upon transcription; only the transcribed text is retained as a message
Guided test resultsAs long as your account is active; immediate purge upon account deletion
Account data (first name, email, date of birth, Google technical identifier where applicable, preferences, time zone, consents, date of last activity and counter of re-engagement emails)As long as the account is active; upon deletion, the account is anonymized
Invoices, payment entries and credit register10 years from the close of the financial year (accounting obligation, Art. L.123-22 of the French Commercial Code) — these documents contain no conversation content
Technical logs30 days
Database backupsDaily backup, retained for 7 days — deleted data therefore disappears from the backups within 7 days of deletion at the latest
Session cookie30 days (see section 16)
Inactive accountsDeletion after 3 years of inactivity, preceded by two email reminders
Transactional emails at BrevoSending logs retained for 12 months at Brevo
Email address of an invited loved oneNot retained by our systems: transmitted to Brevo for the sending of the invitation email, then deleted; only a sending counter without the address is kept for 24 hours (anti-abuse limit) — Brevo's sending logs follow the line above (12 months)
Credit gift (giver's email address, frozen; gift entry)Linked to the payment entries and the credit register: 10 years from the close of the financial year (accounting obligation, Art. L.123-22 of the French Commercial Code); the information message is shown to the recipient only once (until they confirm it), and the origin of the gift — the giver's address — then remains viewable in their credit history
Attribution cookie (acquisition source)6 months
Acquisition source linked to your accountAs long as the account is active; deleted with the account
Visit statisticsAnonymous from the moment they are established (they no longer contain any personal data)
Crisis event log (metadata, without content)12 months
Short excerpts submitted for safety review90 days
Suggestions and feedback that you write to usAs long as your account is active; deleted immediately with the account, or earlier on request
Scheduled reminders (subject, date and time, time zone)30 days after the due date — or after their cancellation — then automatically erased; deleted immediately with the account, and cancellable at any time in "My path"
Notification subscriptionUntil disabled by you ("Disable" button or your browser settings — a subscription that has become invalid is furthermore deleted automatically); deleted with the account

Account deletion and "cryptographic erasure". The deletion of your account (self-service, with double confirmation) entails: the immediate erasure of your conversations, memories, analyses and test results; the anonymization of the account; and the destruction of your encryption key. This destruction renders any possible residual copies permanently undecipherable (cryptographic erasure mechanism, accepted by the CNIL) — including in the backups, which expire in any event within 7 days. Only invoices and payment entries are retained (legal obligation, 10 years), which contain no personal conversation content.

11. How do we protect your data?

In accordance with Article 32 of the GDPR, we apply technical and organizational measures proportionate to the sensitivity of the data:

  • Application-level encryption at rest: your conversations, memories and two-factor authentication secrets are encrypted in AES-256-GCM before storage, with a data key specific to each user and each group, itself protected by a key management service (envelope encryption via Cloud KMS).
  • Encryption in transit: all communications are protected by TLS (HTTPS).
  • Hosting in the European Union: data stored in Paris, daily backups retained for 7 days.
  • Access control: authentication by hashed password, optional two-factor authentication (2FA), separate administration interface with a short session duration.
  • Segregation: private memories are never exposed as is in shared spaces (see section 6).

An important point of honesty: this encryption protects your data at rest (on the disks, in the backups). It is not end-to-end encryption. For Vinca to be able to respond to you, our servers must decrypt your messages and transmit them in plain text (via an encrypted connection) to the AI model provider, for the time needed to generate the response. Any wording leading you to believe otherwise would be unfair — we prefer to tell you clearly (Art. 5.1.a of the GDPR).

In the event of a data breach likely to give rise to a risk to your rights and freedoms, we will notify the CNIL within 72 hours and, if the risk is high, we will inform you directly (Art. 33 and 34 of the GDPR).

12. What are your rights, and how do you exercise them?

You have the following rights over your data (Art. 15 to 22 of the GDPR):

  • Access: obtain confirmation that we are processing your data and receive a copy of it;
  • Rectification: have inaccurate data corrected (your first name, your email and your language can be modified directly in "My account"; the "forget" command allows a memory to be corrected or deleted);
  • Erasure: have your data deleted — the simplest way is the self-service account deletion in "My account" (immediate effect, see section 10);
  • Restriction of processing, in the cases provided for by Article 18;
  • Portability: receive the data you provided to us in a structured, machine-readable format (Art. 20) — self-service from "My account → My data → Export my data (JSON)": profile, private and shared memories, complete conversations, test results, credit and payment register (feature in place since July 5, 2026);
  • Objection to processing based on our legitimate interest (logs, security, acquisition measurement and usage statistics, the sending of invitation emails and the anti-abuse limits — for invitations as for gift verifications; suggestions and feedback that you write to us), for reasons relating to your particular situation (Art. 21); as regards the re-engagement emails (section 7), objection is immediate and requires no reason to be given, via the one-click unsubscribe link included in every email;
  • Withdrawal of consent at any time, without affecting the lawfulness of the prior processing (see section 5).

Procedures. You may exercise these rights:

  • directly in the application ("My account") for rectification, account deletion and the management of memories;
  • by email to contact@vinca.chat or by post (address in section 1) for any other request.

We respond within a period of one month, extendable by two months for complex or numerous requests (you would then be informed — Art. 12.3 of the GDPR). The exercise of your rights is free of charge. In the event of reasonable doubt about your identity, we may ask you for a proportionate verification element (for example, confirming the request from the account's email address); we never request an identity document by default.

13. What happens to your data after your death?

In accordance with Article 85 of Act No. 78-17 of 6 January 1978 (the French "Data Protection Act"), you may define directives concerning the retention, erasure and communication of your data after your death, and designate a person responsible for their execution. General directives may also be registered with a certified digital trusted third party.

The application does not currently offer a dedicated setting for registering these directives. You may send us your particular directives by email to contact@vinca.chat; we will keep them associated with your account. In the absence of directives, your heirs may exercise the rights provided for by law (in particular the closure of the account and objection to the continuation of processing) by contacting us at the same address, with supporting documents.

14. Complaint to the CNIL

If you consider that the processing of your data does not comply with the regulations, you may lodge a complaint with the French supervisory authority (Art. 77 of the GDPR):

Commission Nationale de l'Informatique et des Libertés (CNIL)

3 place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07

Online complaint teleservice: www.cnil.fr/fr/plaintes

You may, if you wish, contact us beforehand (contact@vinca.chat) so that we may try to resolve your difficulty directly — but this is in no way a precondition for referring the matter to the CNIL.

15. Artificial intelligence, profiling and automated decisions

  • No decision producing legal effects or significantly affecting you is taken in a fully automated manner within the meaning of Article 22 of the GDPR. Vinca converses with you, memorizes what you confide to it and adapts its responses; it takes no decision regarding access, pricing or sanction concerning you.
  • General logic of the processing: your messages are transmitted to Anthropic's language models, together with the relevant memories, to generate a personalized response; a background AI then extracts the lasting facts from the conversation to build your memories. The resulting personalization serves exclusively the quality of your support.
  • Your data is never used to train the AI models: neither Anthropic nor OpenAI uses the data transmitted via their APIs for training purposes (a contractual commitment appearing in their Data Processing Addenda), and GHIC trains no model on your data.
  • Security protocol: Vinca's behavior incorporates a crisis protocol — systematic referral to a healthcare professional or the emergency services, permanent display of the help numbers for your country. In order to verify the proper functioning of this protocol, its most serious triggers are recorded in a technical log that never contains the content of your conversations (sections 4 and 10).

16. Cookies and trackers

vinca.chat uses only trackers strictly necessary for the operation of the service or exempt from consent pursuant to Article 82 of Act No. 78-17 and the CNIL's guidelines. No advertising tracker, no third-party audience measurement tool, no social network cookie is placed on this site — that is the reason why you see no cookie banner here.

Cookies placed by vinca.chat

TrackerTypePurposeDuration
User session cookiehttpOnly cookieMaintain your connection securely30 days
Administrator session cookiehttpOnly cookie (administration interface only)Secure administration access12 hours
Google sign-in cookiesEncrypted httpOnly cookies, placed by vinca.chat only, for the duration of the "Sign in with Google" flowSecure the progress of the Google sign-in (protection against tampering with the exchanges); no cookie is placed by Google on vinca.chat5 to 15 minutes (deleted as soon as the flow ends)
Invitation and referral cookieshttpOnly cookiesKeep the code you have activated for the time needed to complete your registration1 hour
Language cookie (NEXT_LOCALE)Preference cookie, readable by the pageRemember the language you have chosen when it differs from that of your browserFor the duration of your browsing session
Attribution cookieFirst-party cookie (placed by vinca.chat only), containing no identifierRemember the source through which you learned of the service (for example a campaign link) in order to measure the effectiveness of our communication actions — statistics produced exclusively on our own behalf, never transmitted to third parties, without tracking of your browsing on other sites6 months, and deleted as soon as you register
Push notification subscriptionRegistration with your browser's notification service, with its explicit permissionReceive the reminders you schedule and the check-ins you have enabled in "My account"Until disabled by you ("Disable" button or browser settings)

Information stored locally by your browser. It is neither transmitted to us nor readable by us remotely, and you can erase it at any time by clearing the site data in your browser: your display settings (light mode, chosen decor); the dismissal of the "First steps" panel; your approximate country and your time zone (in order to display the right scene and trigger your reminders at the right time); the time-stamp of the legal information banner intended for people residing in the United States; and a few technical counters that avoid showing you the same invitation again or counting the same visit twice.

Cache of the installed application (PWA). If you use Vinca as an installed application, a "service worker" stores locally the display files of the site (style sheets, scripts, images of the living room, icons) in order to speed up its loading. It caches neither your pages, nor your conversations, nor any call to our servers: those always go over the network.

Clarifications:

  • your consents are recorded in our database (with a time-stamp), not in a cookie;
  • in order to display the emergency numbers of your country, your IP address may be transmitted to a geolocation service that converts it into a mere country code; no cookie is placed on that occasion;
  • we use no advertising cookie and no third-party tracker. Our audience measurement relies exclusively on anonymous statistics established by our own servers and on the attribution cookie described above, under the conditions of exemption from consent defined by the CNIL (strictly limited purpose, aggregated statistics, no transmission to third parties, no cross-site tracking). We keep no advertising click identifier.

Push notifications (if you enable them): the delivery of notifications goes through the notification service attached to your browser (Google, Mozilla or Apple, depending on your browser), which carries a message that is end-to-end encrypted and generic by default — never does the content of your conversations or of your memories, nor the slightest allusion to their substance, appear on your screen (including when locked). The only exception, in your hands: you can ask, in "My account", for the subject of the reminders you have yourself scheduled to be displayed in the notification ("Call Mom") rather than the neutral text "A reminder is waiting for you". This setting is disabled by default, specific to each person (including between members of a shared space) and reversible at any time; it concerns only your reminders — nothing else ever reaches your lock screen. You can disable the notifications at any time from "My account" or your browser settings; the subscription is then deleted.

Payment (Stripe): when and only when you initiate a payment, the secure form of our provider Stripe is loaded into the page. Stripe then places its own cookies, in particular for fraud prevention, under its responsibility. As long as you do not initiate a payment, no Stripe element is loaded and no Stripe cookie is placed. Consult Stripe's privacy policy: stripe.com/privacy.

Our audience measurement is designed to remain within the scope of the consent exemption defined by the CNIL. Should it ever fall outside that scope (for example through the use of a third-party service or the cross-referencing of data), we would collect your prior consent via a compliant banner.

17. Minimum age: 18 years

vinca.chat is strictly reserved for persons aged 18 years and over. Given the themes addressed (intimacy, relationship life, sexual life), this threshold is deliberately higher than the French age of digital consent (15 years, Art. 45 of Act No. 78-17). At sign-up, you declare your date of birth — sign-up is refused if it does not establish that you are 18 years of age or over — and certify that you are an adult through a dedicated, time-stamped box. Your date of birth is used for no other purpose (see section 4). Any account that appears to be used by a minor will be deleted. If you are a parent or guardian and believe that a minor is using the service, contact us at contact@vinca.chat.

18. Version, date and modifications of this policy

  • Version: 1.9 — modified on August 3, 2026 (interface available in eight languages, no longer six — German and Ukrainian, added to the application on July 18, 2026, had never been reflected in this policy: sections 6 and 18); version 1.8 of August 1, 2026 (section 16 redone after a full inventory of what the application places on or reads from your device: addition of the language cookie NEXT_LOCALE and of the invitation and referral cookies, which were not declared; correction of the description of the payment, now integrated into our own pages and no longer hosted by Stripe, with the clarification that no Stripe element is loaded as long as no payment is initiated; detailed inventory of the information stored locally by the browser and description of the cache of the installed application; mention of the geolocation service used to display the emergency numbers; discontinuation of the retention of any advertising click identifier in the attribution cookie, and deletion of that cookie as soon as you register: section 16); version 1.7 of July 21, 2026 (suggestions and feedback — text that you write to us from "Suggestions", stored encrypted, read by the controller, retained for as long as the account exists and deleted on request; legal basis of legitimate interest; right to object; this form is not an emergency channel: sections 4, 7, 10 and 12); version 1.6 of July 21, 2026 (scheduled reminders — subject, date, time and time zone, stored encrypted, viewable and cancellable in "My path", erased 30 days after the due date; device time zone added to the account data; notification of a reminder in a shared space; content of the notifications now generic by default and no longer by design, the subject of a reminder being displayable at your express request: sections 4, 7, 10 and 16); version 1.5 of July 21, 2026 (re-engagement of inactive accounts — up to three emails inviting you to come back, legal basis of legitimate interest, date of last activity and sending counter added to the account data, cap of three sendings, reset upon a new sign-in, one-click unsubscribe and right to object: sections 4, 7, 10 and 12); version 1.4 of July 19, 2026 (credit gifting between users — email address of the recipient account, giver's address frozen, shown to the recipient and kept in their credit history, technical identifier of the recipient transmitted to Stripe, retention periods: sections 4, 7, 8 and 10; invitation of a loved one by email and referral — loved one's address not retained, anti-abuse limit, information of the third party, right to object: sections 4, 6, 7, 8, 10 and 12); version 1.3 of July 16, 2026 (optional Google sign-in — data received, legal basis, Google's role, absence of trackers: sections 4, 7, 10 and 16; addition of the date of birth to the data collected, for age verification: sections 4, 7, 10 and 17); version 1.2 of July 10, 2026 (optional push notifications: sections 4, 7, 10 and 16); version 1.1 of July 10, 2026 (first-party acquisition measurement and safety logging of the crisis protocol); version 1.0 validated on July 5, 2026 by the controller and published on July 8, 2026.
  • The history of the versions of this policy is kept and remains available for consultation on request.
  • In the event of a substantial modification (new processor, new purpose, new transfer outside the EU, modification of retention periods), we will inform you individually — notification in the application and/or email — before the modification takes effect. Any new purpose based on consent will be the subject of distinct and prior consent collection; your continued use will never constitute consent to any new processing of sensitive data.
  • This policy is drafted in French, the reference language. It is translated into the eight languages of the interface (French, English, Spanish, Russian, Italian, Portuguese, German, Ukrainian); in the event of a discrepancy, the French version prevails. The translations will be produced from this validated French version.

*Document permanently accessible from the footer of vinca.chat and from the application's settings. For any question: contact@vinca.chat.*

Version 1.9

v2.3.0